AAFROSOC CRM
TermsSupportHome
Privacy PolicyScopeInformation we handleHow information is usedGoogle API dataSharingRetentionSecurityYour choicesChangesContact

Privacy Policy

Effective: September 16, 2026 · Applies to AFROSOC CRM at afrosoc-crm.leftface.tv

AFROSOC CRM is an internal relationship-management and organizing coordination system intended for authorized AFROSOC users. This Privacy Policy explains what information the service may process, why it is used, and the choices available to users and people whose information is maintained in the CRM.

1. Scope

This policy applies to the AFROSOC CRM website, authentication flow, and CRM functions operated under afrosoc-crm.leftface.tv. The public demonstration pages may use fictional sample records and do not require a user account.

2. Information we handle

Depending on how the CRM is configured and used, the service may process:

  • Account and authentication information: name, email address, account identifier, authentication status, and authorization information for users who sign in.
  • Organizer-managed contact records: names, contact details, geographic or chapter information, communication preferences, organizing status, assignments, outreach history, event participation, notes, and other information relevant to organizational relationship management.
  • Voluntarily provided organizational information: information a person chooses to provide through an interest form, membership process, event registration, or direct communication. This may include organizational affiliation or other information the person elects to share.
  • Technical and security information: timestamps, IP address or device/network information where logged by hosting or authentication services, application events, error information, and security/audit logs.
  • Google user data: only the data authorized through Google OAuth and required for enabled CRM features, as described below.

3. How information is used

Information is used to operate and secure the CRM; authenticate authorized users; maintain relationship and outreach records; coordinate follow-up, assignments, events, and organizing work; communicate with people who have provided contact information; troubleshoot the application; maintain audit and security records; and comply with applicable legal obligations.

The CRM is not intended to sell personal information, build advertising profiles, or serve targeted advertising.

4. Google API Data Use

AFROSOC CRM’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

When a user chooses to authenticate with Google or an administrator enables a feature that uses a Google API, AFROSOC CRM may request access to Google user data associated with the scopes displayed on the Google authorization screen.

Access

The application accesses only the Google user data necessary for the CRM features the user or organization has enabled. At minimum, authentication may involve basic account identity information such as name, email address, and account identifier. If additional Google API scopes are enabled, the authorization screen will disclose those scopes before access is granted.

Use

Google user data is used only to provide or improve user-facing CRM features that are visible and relevant to the authorized user, such as authentication, account identification, and any explicitly enabled workflow that depends on the requested scope. Google user data is not used for advertising, creditworthiness, or unrelated profiling.

Storage and retention

Where Google user data must be stored to provide an enabled feature, the application should retain only the data reasonably necessary for that feature and for legitimate security or audit needs. OAuth tokens and credentials must not be exposed in public pages or client-side source code. Retention is further described in Section 6.

Sharing and transfer

Google user data is not sold. It is not transferred to third parties except as necessary to provide or secure the service, with the user’s consent, as part of a lawful organizational administration need consistent with the requested feature, or when required by law. Service providers acting on behalf of the application may process limited information only to provide hosting, authentication, security, or other operational services.

Human access

Human access to Google user data should be limited to situations where it is necessary to provide user-requested support, investigate abuse or a security incident, comply with law, or perform internal operations where the data has been appropriately aggregated or protected, and only by authorized personnel with a legitimate need.

5. When information may be shared

Information may be shared with authorized AFROSOC personnel who need it for legitimate organizational responsibilities; with service providers that host, authenticate, secure, or support the CRM; when a person directs or consents to the sharing; to protect the rights, safety, integrity, or security of users or the service; or when disclosure is required by law. The service is not designed to make CRM records public.

6. Retention and deletion

Information should be retained only for as long as reasonably necessary for the organizational purpose for which it was collected, applicable recordkeeping requirements, security, dispute resolution, or legal obligations. Authorized administrators may correct, archive, or delete records when they are no longer needed. Users may also revoke Google account access through their Google Account permissions. Revoking access stops future API access but may not automatically delete information already retained for a legitimate purpose.

Requests to delete or correct information can be made using the process described on the Data Deletion & Correction page.

7. Security

AFROSOC CRM is intended to use reasonable administrative, technical, and organizational safeguards appropriate to the sensitivity of the information it processes. These safeguards may include HTTPS, authenticated access, authorization controls, least-privilege permissions, audit logging, secure credential handling, software updates, and access review. No system can guarantee absolute security.

8. Your choices

Depending on your relationship to AFROSOC and applicable law, you may request access to, correction of, or deletion of information associated with you. Authorized users can stop using Google authentication or revoke previously granted Google access through their Google Account. Certain information may be retained where required for security, legal compliance, or legitimate organizational recordkeeping.

9. Changes to this policy

This policy may be updated when CRM functionality, data practices, or legal requirements change. Material changes should be reflected by updating the effective date and, where appropriate, notifying affected users before the change takes effect.

10. Contact

Privacy, access, correction, deletion, and support requests may be submitted through the AFROSOC CRM Support page. The CRM administrator responsible for a user’s organization may also provide an internal support channel.

AFROSOC CRM public policy page.
HomeTermsSupportData deletion